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This l isting of claims will replace all prior veniions and listings of claims in the 

application: 
ListiBg of Claims: 

1-22. (Canceled) 

23- (Currently Ajnended) A securit>' system for a computer network, the network having a 
plurality of deWces connected thereto, the security system comprising: 

(a) a security subsystem connected to at lea<;t ftome of the devices in the network, the security 
subsystem configurel to monitor activities of the at least some devices on the network and detect 
attacks on the at leas ; some devices; 

(b) a master system \r'hich monitors the integrity of the security subsystem and registers 
information pertainirg to attacks detected by the security subsystem; and 

(c) a first secure link connected between the security subsystem and the master system, the 
master system monitoring the integrity of the securit)' subsystem and receiving the information 
pertaining to the attaitks through the first secure hnk^ 

wherein the master s; /s_t em further moniior^ whether the sec u rity subsystem responds to the 
masrer system, the m^^er systrm taking action if no rt?sponsc is deiectgd. 

24. (Canceled) 

25. (Previously Presented) The system of claim 23 whereiti the master system does not take 
direction from the seourity subsysleniT 

26. (Previously Presented) The system of claim 23 further comprising: 

(d) a second secure link connected between the master system and the network which enables 
data communication from the master system to the netAvork for issuing instructions to the 
netwoiic devices. 

27. (Previously Presented) TTie system of claim 26 wherein the instnictions are issued if the first 
secure link is severed or compromised. 
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28. (Previously Presented) The system of claim 23 wherein the master system is hierarchically 
independent from the security subsystem. 

29. (Previously Presented) The system of claim 23 wherein the security subsystem is 
hierarchically subordinate to the master system. 

30. (Previously Presented) The system of claim 23 wherein the first .-secure link is defined by a 
virtual private netwo-k (VPN) tunnel. 

31. (Canceled) 

32. (Previously Presented) The system of claim 23 wherein the master system further comprises 
a pseudo-attack generator which generates attacks on the network, the security subsystem 
detecting such attack; and sending expected replies to the ma.ster system when its integrity is 
intact, the master sys:em detecting whether the expected replies are received in response to a 
pseudo-attack to determine whether the integrity of the subsystem hx<i been compromised. 

33. (Currently Amen led) A security system for a computer network, the network having a 
plurality of devices connected thereto, at least some of the devices having security-related 
functions, the sccurit/ system comprising: 

(a) a security subsystem associated with at least some of the dev-ices in the network which tests 
the integrity of the security-related functions; 

ar) a master s>'stem v.hich monitors the integrity of the security subsystem and receives and 
stores results of the i)itegrity testing of the devices having security-related functions; and 
(c) a secure link conrected bet^veen the security subsystem and the master system, the master 
system monitoring the integrity of tlw security sub.'system and receiving the results of the 
integrity testing of th- devices having security-related flinctions through the first secure link, 
^vhersLn_ the security mb system or the master sx^fem initiate, ^^v ntermca .ures upon detecting 
IlmhAMcfinjvofadevi^ 
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34. (Canceled) 


35. (Previously Pres mted) The system of claim 33 wherein the security subsystem tests the 
integrity of the secutity-rclated functions by generating psewdo-attacks on the devices having 
security-related functions. 

36. (Canceled) 

37. (Currently Amer dcd) The system of claim 34 33.wherein the countenneasurcs include 
restricting or disablijig access to the nctxvork or a device in the netv.'ork. 

38. (Previously Presented) Tlie system ofclaim 33 wherein the master system fialher comprises 
a pseudo-attack generator which generates attacks on the nenvork. the secunty subsystem 
detecting such attacks when fimcnonin? properly, the master system comparing the pseudo- 
anacks made on the network to the attacks actually detected by the subsystem, the master system 
thereby determining vv)iethcr the integrity of the subsystem has been compromised. 

39. (Previously Prestnted) The system of claim 33 wherein the secure link is defined by a virtual 
private neuvork (VPN) tunnel. 

40. (Previously Presented) The system ofclaim 33 wherein at least one of the devices having 
security-related ftmciions is a firewall. 

41. (Previously Presented) The system ofclaim 33 wherem at lea.st one of the devices having 
set^urity-related fiinclions is a network intrusion detection system. 

42. (NeN^O A security system for a computer network, the neUvork having a plurality of devices 
connected thereto, tht; security system comprising; 

(a) a security subsyst-m connected to at least some of the devices in the network, the security 
subsystem configurer to monitor activities of the at least some devices on the network and detect 
anacks on the at least some devices; 
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(b) a master system ^vhich monitors the integrity of the security subsystem and registers 
information pertaining to attacks detected by the security subsystem; and 

(c) a first secure link connected between the security subsystem and the master system, the 
master system monitDring the integiity of the security subsystem and receiving the information 
pertaining to the aUa;ks through the first secure link, 

v^'herein the security subsystem or the master system initiates countenneasures upon detecting 
that the integrity of t ie at least some devices on wliich an attack has been detected has been 
compromised. 
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